CVE-2013-7225

Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
fatfreecrmfat_free_crm
𝑥
≤ 0.12.0
fatfreecrmfat_free_crm
0.9.6
fatfreecrmfat_free_crm
0.9.7
fatfreecrmfat_free_crm
0.9.8
fatfreecrmfat_free_crm
0.9.9
fatfreecrmfat_free_crm
0.9.10
fatfreecrmfat_free_crm
0.10.1
fatfreecrmfat_free_crm
0.11.0
fatfreecrmfat_free_crm
0.11.1
fatfreecrmfat_free_crm
0.11.2
𝑥
= Vulnerable software versions